In order that you as a service user and data controller (referred to as “Controller” or “you” or “User”) may use or continue to use our a) Tattoo Simulator and Try on History; b) maintain your presence on our Find Tattoo Artists directory; and c) use our auxiliary services (“Services”) offered by us, Convinced Creations Company Limited, 9th Floor, Amtel Building, 148 Des Voeux Road Central, Central, Hong Kong and data processor (referred to as “Tatship” or “Processor”), you agree that certain Personal Data you submit as part of your use of our Services and these data processing terms (“Terms”) shall apply (notwithstanding any other terms and conditions applicable to the delivery of the Services to the contrary) in order to address the compliance obligations imposed upon Tatship and its Users pursuant to applicable Data Protection Law and in particular, Regulation (EU) 2016/679 (“GDPR”) and Hong Kong's Personal Data (Privacy) Ordinance (“PDPO”).
These Terms shall constitute a separate agreement, or they may be incorporated by reference in the relevant Services agreement, as the case may be.
DEFINITIONS
APPOINTMENT
DURATION
The Terms shall commence on the Effective Date and shall continue in full force and effect until such time as all Services have ceased and all Personal Data in the Processor’s possession or within its reasonable control has been returned or destroyed (the “Term”).
DATA PROTECTION COMPLIANCE
SUBPROCESSORS
SECURITY INCIDENTS
INTERNATIONAL DATA TRANSFERS
AUDIT
Users may, on an annual basis or more frequently as reasonably requested by User, at User’s expense, conduct an audit to verify that Tatship is operating in accordance with this PDPO. Such audit(s) may include a review of all aspects of Tatship’s performance, including, but not limited to, Tatship’s general controls and security practices and procedures. Tatship will cooperate with User in conducting any such audit, and will allow User reasonable access, during normal business hours and upon reasonable notice, to all pertinent records, documentation, computer systems, data, personnel, and areas used to Process the User Data areas as User reasonably requests to complete such audit. User will take reasonable steps to prevent the audit from materially impacting Tatship’s operations.
Tatship shall correct any deviations from Security Best Practices that are identified in any security audit as soon as practicable, but in no event more than five days after receiving notice from User outlining any deviations (provided, however, that if five days is not a practicable cure period, then Tatship may instead present a remediation plan to User within such five day period that sets forth an achievable and reasonable timeframe, and Tatship must thereafter diligently proceed to correct any deviations in accordance with such plan).
INTERNATIONAL DATA TRANSFERS
the by the User approved data environment; or
any territory in which restrictions are imposed on the transfer of Personal Data across borders under Data Protection Laws,
without the prior written consent of the User.
Tatship will ensure that Contractual Clauses or other applicable transfer mechanisms, are in place to ensure adequate level of data protection.
INDEMNITY
Notwithstanding any provisions of the relevant Services agreement to the contrary, Processor shall and hereby agrees to indemnify User and Instructing Parties and their officers, employees, agents and subcontractors (each an “Indemnified Party”) from and against any claims, losses, demands, actions, liabilities, fines, penalties, reasonable expenses, damages and settlement amounts (including reasonable legal fees and costs) incurred by any Indemnified Party as a result of any gross negligence or wilful breach by Processor of these Terms.
MISCELLANEOUS
SCHEDULE
Data subjects whose Personal Data is uploaded by data exporter to, or otherwise received directly or indirectly from data exporter (including from a Permitted User on data exporter’s behalf) by or through the Services, or provided by data exporter to Tatship to input into the Services.
The data exporter may transfer Personal Data to Tatship, the extent of which is determined and controlled by the data exporter in its sole discretion. Such Personal Data may include any category of Personal Data the data exporter or its Permitted Users may enter into the Services.
The data exporter may transfer Personal Data to Tatship, the extent of which is determined and controlled by the data exporter in its sole discretion. Such Personal Data may include any category of Personal Data the data exporter or its Permitted Users may enter into the Services.
Continuously, for the length of the Agreement between the Parties.
User Personal Data transferred will be processed to (i) provide the Services to the data exporter and fulfil the data importer’s obligations under the Agreement; and (ii) comply with applicable law.
User Personal Data transferred will be processed to (i) provide the Services to the data exporter and fulfil the data importer’s obligations under the Agreement; and (ii) comply with applicable law.
User Personal Data will be retained for the length of time necessary to provide Services under the Agreement and in accordance with Tatship’s data retention processes and as otherwise required by applicable law.
Tatship’s sub-processors will process User Personal Data to assist Tatship in providing the Services pursuant to the Agreement, for as long as needed for Tatship to provide the Services.
Tatship currently uses sub processors to provide core infrastructure and other services. Prior to engaging any subprocessor, Tatship evaluates their privacy, security, and confidentiality practices, and executes an agreement with the subprocessor governing applicable privacy and security obligations, including an appropriate data transfer mechanism where required. Tatship may use the following sub processors for hosting User data and providing or supporting the core infrastructure that helps deliver the Tatship services: Amazon Web Services (AWS) (Amazon Web Services, Inc. 410 Terry Avenue North, Seattle, WA 98109-5210, USA)
CROSS BORDER DATA TRANSFER MECHANISMS
BINDING CORPORATE RULES
STANDARD CONTRACTUAL CLAUSES